1.6 KiB
1.6 KiB
Campaign Access Explanation Coverage
Campaign access explanations are resource-specific evidence. They inherit the parent Campaign decision only where the child has no independent grant model, and they must identify that inheritance explicitly.
Implemented
- Campaign
- Campaign version
- Campaign delivery job / built message
- Computed Campaign report, identified by Campaign, version, and report kind
Planned Slices
- Recipient rows and imported recipient-source snapshots
- Attachment bindings and frozen attachment resolutions
- Validation issues, review decisions, and attachment-policy overrides
- Delivery attempts, IMAP append attempts, Postbox attempts, and reconciliation decisions
- Campaign shares and ownership-transfer records
- Import mapping profiles and import executions
- Reusable Campaign templates and template revisions when the template library becomes persistent
- Export packages and protocol/report artifacts
Each child explanation must include:
- the child resource identity and current state;
- the parent Campaign and version where applicable;
- whether access is inherited, independently granted, or further restricted;
- effective owner/share/policy provenance;
- missing-module or unavailable-evidence reasons without leaking the hidden object;
- a stable resource identifier suitable for audit and support links.
Delivery attempts, review decisions, reports, and exports can contain more sensitive evidence than the Campaign summary. Their read and diagnostic/export permissions therefore remain independently enforceable even when the parent Campaign is readable.